Privacy Policy
Reference translation. The Korean original prevails in case of any difference.
Effective date: October 11, 2026 · Version 1
주식회사 메타뷰 (MetaVu Inc.; brand: MetaVu (메타뷰); the "Company") complies with the Personal Information Protection Act and other applicable laws of the Republic of Korea in providing the SAYNARY service (the "Service"), and has this Privacy Policy in place to protect users' personal information.
At a glance
- Speech recognition (transcription), speaker separation, search indexing and voiceprints are processed on the Company's servers (Republic of Korea).
- AI minutes, summaries, answers to questions and context correction use the Claude API of Anthropic, PBC (USA). Before sending, resident registration numbers, card numbers, account numbers, phone numbers and email addresses are masked (default). Audio files are never sent.
- Recordings in which security keywords were detected, or whose organization has turned external AI off, are not sent outside and are processed only on the Company's servers.
- Recordings and conversation content are not used for AI training (unless you separately consent).
- We do not sell personal information to other companies or use it for advertising, and we use no advertising or analytics cookies.
- We do not collect location information.
1. Personal Information We Process and Why
1-1. Information you enter or that is created while you use the Service
| Category | Items | Purpose |
|---|---|---|
| Sign-up and sign-in | Email, password (one-way encrypted), name, workspace (organization) name, records of consent to the Terms and the Privacy Policy (version and time) | Identifying members, sign-in, email verification and password recovery, delivering notices |
| Organization members | Role in the organization (owner, admin, member), team and team-lead status, invitation email, records of consent to the organization notice | Organization management, permissions according to visibility |
| Recordings | Recorded audio, sound of imported audio and video files, recording title, date, length and recording device type, participant names, records of recording-rights confirmation | Storing, playing and downloading recordings |
| Information created from recordings | Transcript text, speaker separation and speaker names, minutes, briefs, cards and summaries, action items, decisions, issues and commitments (memory), projects, conversation type, recording quality records | Providing transcripts and minutes, search, tracking action items and decisions, briefings |
| Ask AI | Questions (typed, or voice input converted to text), answers, conversation history, period summaries | Q&A, providing conversation history |
| Calendar | Event title, time and notes, calendar entry settings | Adding action items and commitments to the calendar |
| Recording status information | Input sound level during recording (not the content of speech), battery and charging status, remaining storage, network type, microphone route, alert records | Recording failure alerts, stall notifications to your other devices, recording quality display |
| External integrations (if you connect them) | Google account email and authentication tokens, Notion token and page id, Slack webhook URL, webhook URL and signing key (all stored encrypted) | Calendar entries and sending minutes as you instruct |
| Organization AI key (if registered) | The organization's Claude API key (stored encrypted) | Providing AI features with the organization's key |
| Personal settings | Settings such as notifications, summary style, email summaries and language; whether you consent to training use (not consented by default) | Personalized settings |
| Voiceprint (only with separate consent) | Voice features (embeddings) — sensitive information (biometric information). The original audio is not stored | Automatically naming speakers. See the Voiceprint Processing Notice for details |
| Inquiries | Email, name, content of the inquiry | Handling inquiries and complaints |
1-2. Information created automatically while you use the Service
| Items | Purpose |
|---|---|
| IP address, access time, browser information (User-Agent) | Security (preventing unauthorized sign-in, rate limiting), audit records |
| Name and type of signed-in devices (Android, iOS, watch, PC, web), last used time | Managing and revoking devices |
| Audit records (sign-up, sign-in, settings changes, deletions, exports and other important actions) | Investigating security incidents, handling disputes |
| Access logs (records of people other than the recorder viewing a recording: who, when, what, IP) | Ensuring the recorder can check access, controlling admin access |
| AI usage (AI processing time per recording, number of questions) | Managing monthly usage limits |
1-3. Other people's information contained in recordings
Recordings may contain the voices and statements of people who are not users, such as the other party or participants in a conversation, and personal information mentioned in them. The Company processes this information only for the purpose of providing the Service — storing, transcribing and summarizing the user's recording. It is up to the user who records to inform the other party and obtain consent before recording (Terms of Service, Article 7). A person captured in a recording may ask the user who recorded it, or the Company (support@metavu.io), for access, deletion and so on.
1-4. Information we do not collect
- We do not collect location information.
- We do not ask for resident registration numbers (if one comes up in a conversation, it is masked before being sent to AI).
- We do not read your phone contacts, photos or text messages.
2. Retention Period and Destruction
As a rule, information is destroyed without delay once the purpose of use has been achieved. The periods that follow from the Service's features are:
| Information | Retention period |
|---|---|
| Account information | Deleted after the 7-day grace period following a deletion request (signing in during the grace period cancels the deletion) |
| Recordings (audio, transcripts, minutes, cards, memory, chats, calendar events, search index) | Until you delete them. Once deleted, permanently deleted after 30 days in the trash |
| Recordings subject to an organization retention period | Moved to the trash once the period set by the organization (at least 30 days) has passed since the recording was created, and permanently deleted 7 days later. If the organization sets no period, until deleted |
| Audio of recordings set to "Text only" | Deleted as soon as transcription (including precise re-transcription) is finished |
| Recordings under legal hold | Until an organization admin lifts the hold (handling disputes and legal obligations) |
| Organization recordings of members who deleted their account | Deleted together with the account (default) or transferred to the organization owner, according to the organization's policy |
| Organization deletion | All of the organization's information is deleted after the 30-day grace period following the deletion request |
| "Export my data" files | 7 days after creation |
| Voiceprints | Deleted immediately when the person, the person who enrolled it or an admin deletes it. Deleted automatically if unused for the period set by the organization after last use (1 year by default, 30 days to 10 years). Deleted 30 days after the organization turns the feature off |
| Audio used to enroll your own voice | Deleted right after the features are created |
| Voice input (dictation) audio | Deleted right after conversion to text (not stored) |
| Share links | Until the expiry time you set (or until deleted) |
| External integration tokens | Deleted immediately when disconnected or on account deletion (for Google, a token revocation request is sent) |
| Web sign-in sessions | 14 days (extended when used); ends immediately on sign-out or revocation |
| Email verification, password reset and invitation links | 48 hours · 1 hour · 7 days |
| Access logs | The same period as the organization's retention period. Where there is no retention period, [확인 필요] |
| Audit records | [확인 필요]. After account deletion only an identifier from which the email cannot be recovered remains |
| AI usage records | While the workspace exists (the usage time remains even if recordings are deleted — no content) |
| Access records (sign-in records, IP, etc.) | The retention period for communication confirmation data under the Protection of Communications Secrets Act (3 months) [확인 필요] |
How information is destroyed: Electronic files are deleted in a way that cannot be restored, and database records are deleted. A cleanup job runs once a day to delete recordings, voiceprints and records whose period has passed, and the fact of deletion is kept in the audit records (without content such as recording titles). Backups are deleted in turn within [확인 필요: backup cycle and retention period].
3. Provision to Third Parties
The Company does not provide users' personal information to third parties, with the following exceptions:
- Transfers you instruct yourself: sending to Google Calendar, Notion, Slack or webhooks that you connected and enabled yourself, share links you create, and email drafts you send. These are sent from your account on your instructions, and information left in the receiving service follows that service's policies.
- Where the law provides otherwise, or an investigative authority requests it following the procedures set by law
4. Outsourcing and Overseas Transfer
4-1. Outsourcing of processing
| Recipient | Outsourced work |
|---|---|
| Anthropic, PBC (USA) | Generative AI processing such as AI minutes, summaries, titles and cards, Q&A, context correction, speaker name suggestions and conversation type classification |
- Speech recognition (transcription), speaker separation, search indexing (semantic search embeddings), voiceprints and dictation are processed on servers operated by the Company (GPU, Republic of Korea) and are not outsourced.
- Emails (verification, notifications, meeting summaries) are sent through the Company's mail server.
- The Company operates the servers, the domain connection (tunnel) and mail itself; there is currently no separate hosting outsourcing. If outsourcing arises, for example by moving to the cloud, it will be added to this table and announced in advance.
- The Company sets out and manages personal information protection obligations, restrictions on sub-outsourcing and security measures in its outsourcing agreements. If the outsourced work or the recipient changes, it will be announced through this Privacy Policy.
4-2. Overseas transfer (Article 28-8 of the Personal Information Protection Act)
To perform the service agreement, the Company transfers personal information overseas (outsourced processing and storage) as follows.
| Item | Details |
|---|---|
| Recipient | Anthropic, PBC |
| Recipient's contact | Privacy: privacy@anthropic.com [확인 필요] · Address: [확인 필요] |
| Country of transfer | United States |
| Items transferred | Transcript text to the extent needed for the AI feature in use (including segment numbers and times), speaker and participant names, recording title, date and conversation type, minutes and memory items, glossaries, and your questions and conversation history. Resident registration numbers, card numbers, account numbers, phone numbers and email addresses are replaced by masked labels (e.g. [phone number]) before sending (organization policy default). Audio files and voiceprints are not sent |
| When and how | Each time an AI feature runs (creating minutes after a recording ends, questions, correction, etc.), sent over the network as TLS-encrypted API calls |
| Purpose of use | Creating minutes, summaries, titles and cards, Q&A, context correction, speaker name suggestions, conversation type classification, and checking general knowledge when web search is on (search queries are instructed not to contain recording text or people's names) |
| Retention and use period | Anthropic does not use data received through the API for model training, and keeps it only for the period set by Anthropic's policies (e.g. for abuse monitoring) before deleting it. Details follow Anthropic's Commercial Terms and Privacy Policy [확인 필요: state the current retention period] |
| How to refuse | ① If an organization admin turns off "Use external AI" in the organization policy, none of that organization's recordings are transferred overseas. ② Recordings caught by the organization's security keywords are automatically not transferred. ③ Individual users can request refusal at support@metavu.io, and the Company will turn off external AI for that workspace. |
| Effect of refusal | Speech recognition, speaker separation, search, recording and playback remain available. Minutes and summaries are replaced by rule-based processing on the Company's servers, which may lower quality, and generative AI features such as Ask AI, AI context correction and asking across several recordings are unavailable. |
- If an organization registers and uses its own Claude API key, the terms of the agreement between that organization and Anthropic also apply to data processed with that key.
- On each recording's privacy screen (🔒) you can check where that recording was processed (on-premises / Claude API).
5. Access in Organization Workspaces
- In an organization, organization admins and the team lead of the recorder's team can view recordings according to the visibility set by the organization. "Only me" (private) recordings cannot be viewed even by admins. Ordinary members cannot view other people's recordings.
- The organization can set a notice informing members of such access and obtain their consent; members who do not consent cannot create new recordings.
- When someone other than the recorder opens a recording, an access log is kept, and the recorder can check who can see it (including why) and who has viewed it. Access logs cannot be deleted.
- An organization admin's AI questions are answered only from recordings they can see, and the questions themselves are kept in the audit records.
- The organization decides the purpose and scope of viewing and managing members' conversations in an organization workspace. The organization must inform its members and obtain any necessary consent in accordance with applicable laws (the Personal Information Protection Act, labor laws, etc.).
6. Data Subjects' Rights and How to Exercise Them
Users (and their legal representatives) can exercise the following rights at any time. Most can be exercised directly in the app, and you can also make requests by email.
| Right | How to do it in the app |
|---|---|
| Access | Settings > Account > My data overview (number of recordings, memory, voiceprint, integrations, devices, share links, consent records) · Recording details > 🔒 Privacy (who can see it, access log, scheduled deletion date, where AI processed it) · Settings > Devices |
| Correction | Edit transcripts, speaker names, minutes and memory items directly; Settings > Account (name, password) |
| Deletion | Delete recordings (trash → permanent deletion), Settings > Voiceprint > Delete, disconnect integrations, clear chat history, Settings > Account > Delete account |
| Suspension of processing | Change a recording's visibility to "Only me" (if the organization allows it), "Text only" (deletes the audio), turn off email summaries, turn off automatic calendar entries, refuse external AI (see 4-2) |
| Withdrawal of consent | Withdraw voiceprint consent (deletion), turn off consent to training use, disconnect integrations, delete your account |
| Portability (export) | Settings > Account > Export my data (ZIP: per-recording transcripts, minutes, cards, chats and, if selected, audio; memory; calendar events; settings; account information) |
- Requests by email: support@metavu.io (please write from the email you signed up with so that we can verify your identity). The Company will notify you of the result within 10 days of receiving the request; if it cannot be handled within that period, it will tell you why and when it expects to finish.
- You may make requests through a representative (a legal representative or a person you have authorized); in that case documents proving the authorization may be requested.
- Requests may be limited for information that must be kept by law, or where other people's rights could be infringed (e.g. an organization's recordings under legal hold, recordings made by someone else); we will tell you the reason.
- For recordings in an organization workspace you may also make requests to the organization admin.
7. Children Under 14
The Service does not accept sign-ups from children under 14. If we learn that a child under 14 has signed up, we delete the account and its information without delay.
8. Automatic Collection Devices (Cookies)
The web (https://saynary.metavu.io) uses only the following cookies. No advertising, behavioral analytics or third-party tracking cookies are used.
| Cookie | Purpose | Duration |
|---|---|---|
vn_session | Keeping you signed in (HttpOnly, Secure; cannot be read by scripts) | 14 days (extended when used); deleted on sign-out |
vn_csrf | Preventing forged requests through other sites (CSRF) | Same as the sign-in session |
You can block cookies in your browser settings, but you then cannot sign in on the web (the apps use device tokens instead of cookies).
9. Security Measures
| Category | Measures |
|---|---|
| Administrative | Appointment of a chief privacy officer, minimizing persons with access, internal management plan [확인 필요] |
| Technical — encryption | Passwords one-way encrypted (argon2id); only hashes of sign-in tokens and links are stored; AI keys, integration tokens and voiceprints are stored encrypted with the server master key; TLS encryption in transit. Recording files encrypted at rest (AES-256): recording audio files (chunks, files used for merging, imported originals, "Export my data" files) are stored encrypted with AES-256-GCM under a different key for each file, and those keys are themselves encrypted with the server master key |
| Technical — access control | Complete separation between workspaces (organizations), access rights according to visibility, team leads have read-only access, 15-minute lock after 5 failed sign-ins, rate limiting, sign-out of other devices when the password is changed or reset |
| Records | Audit records of important actions, access logs of other people's recordings (the recorder can check them) |
| Minimizing external transfer | Masking personal information before sending to AI (default), blocking external transfer of recordings with security keywords or under policy, option to mask personal information when sharing and exporting (on by default) |
| Physical | Access control to the server location [확인 필요] |
10. Not Used for AI Training
- The Company does not use your recordings, transcripts, minutes or questions to train AI models. Anthropic also does not use data received through the API for training.
- Exception: only if you separately consent to training use in the settings and your organization allows it may the transcripts of those recordings and your correction history be used to improve the Service's conversation-scene judgment feature. The default is "Do not use", and you can turn it off at any time. Imported files and "Only me" recordings are not included.
11. Chief Privacy Officer
| Item | Details |
|---|---|
| Chief privacy officer | 노진송 (대표이사) |
| support@metavu.io | |
| Phone | 1899-9603 |
Please send inquiries, complaints and requests for remedies concerning personal information to the contacts above. We will respond and handle them without delay.
12. Remedies for Infringement of Rights
If you need counseling or dispute resolution because of an infringement of personal information, you can contact the following organizations (in Korea).
| Organization | Contact |
|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 (no area code) · www.kopico.go.kr |
| Personal Information Infringement Report Center (Korea Internet & Security Agency) | 118 (no area code) · privacy.kisa.or.kr |
| Supreme Prosecutors' Office | 1301 (no area code) · www.spo.go.kr |
| Korean National Police Agency | 182 (no area code) · ecrm.police.go.kr |
13. Changes to This Privacy Policy
When this Privacy Policy changes, we announce it by app banner and email from 7 days before the effective date, and for important changes (items collected, overseas transfer, provision to third parties, etc.) we ask for your confirmation again on a consent screen after sign-in. Earlier versions can be viewed under "Earlier versions" on this page.
| Version | Effective date | Description |
|---|---|---|
| 1 | 2026-10-11 | First version |
Appendix A. Additional Processing by Feature (draft of 2026-10-05 · [법률 검토 필요 · legal review required])
This appendix is a draft that collects the processing added by v1.0 (meeting productivity), v11 (enterprise), Knowledge, Works (work videos), contribution recognition and rewards, and the knowledge marketplace (CEO decision of 2026-10-05: Knowledge, Works, rewards and the marketplace are opened to the public). After legal review it will be merged into the tables of the main text (sections 1–6 and 9). Until then the main text prevails.
A-1. Additional information processed and why
| # | Feature | Items | Purpose | Retention / destruction | External transfer |
|---|---|---|---|---|---|
| 1 | Meeting notes & agenda | Notes you enter (with the time during the recording) and agenda items; the AI's agenda matching and note enrichment | Organizing the minutes | Deleted with the recording | Only recordings that allow external AI are sent to Anthropic (USA) ("notes and agenda" added to the items in 4-2); blocked recordings use server rules only |
| 2 | Minutes approval | Who approved, when, and the note; edit history after approval | Finalizing and auditing minutes | Deleted with the recording | None |
| 3 | Comments & @mentions | Author, text, target (transcript span / minutes item), people mentioned; mentions received and read time; mention emails (instant / daily digest) | Collaboration | Deleted with the recording. Comments, notes and approvals left on other people's recordings remain after account deletion, anonymized as "deleted user" (they are posts) | None (mail via the Company's mail server) |
| 4 | Conversation analytics | Per recording: speaking share, turns, interruptions, questions, longest monologue, efficiency score (computed on the server). Organization totals only when an admin turns them on; no per-person figures | Better meetings | Deleted with the recording | None. Use for individual evaluation or HR purposes is prohibited |
| 5 | Minutes translation | Minutes text, translations (cache), share links in the translated language | Multilingual minutes | Deleted with the recording | Anthropic (USA) — "translation" added to the items in 4-2 |
| 6 | Reference documents | The extracted text of uploaded documents (PDF, DOCX, TXT), their names and uploader (the original file is deleted right after extraction) | Background for minutes and Q&A | Deleted when the recording / project is deleted | Only relevant excerpts, only for recordings that allow external AI, to Anthropic. Documents may contain third parties' personal information, so upload only material you are authorized to share |
| 7 | Audio URL import | The URL and host you enter; the downloaded media (handled and encrypted like a recording) | Importing recordings | Same as recordings | The Company's server connects to the server of that URL |
| 8 | Two-step verification | TOTP secret (encrypted), recovery code hashes, verification attempts (time, IP) | Account protection | Deleted when turned off or on account deletion | None |
| 9 | SSO | Email, name, sub, Google hd / Microsoft tid from the IdP. The email domains an organization links to SSO and the domain ownership check (DNS TXT) record (check token, time, lookup result) | Sign-in and automatic account creation; preventing impersonation of someone else's domain | Deleted when unlinked or the organization is deleted | The Company's server queries DNS (not personal information). The customer chooses its IdP and gives notice of that outsourcing |
| 10 | Sign-in records | IP, User-Agent and first / last use per sign-in and session | Security (session management, new sign-in alerts, abuse prevention) | Deleted when the session is revoked / expires or on account deletion; audit records per section 2 | None |
| 11 | New sign-in alert email | Time, device type, IP (no recording content) | Account protection (optional) | Same as mail delivery records | None |
| 12 | Push notifications | Device push token (FCM / APNs) and notification settings per kind | Notices for ready minutes, mentions, review requests, recording status and safety remarks (admins) | Deleted when the device is revoked or on account deletion; tokens that fail are revoked automatically | Google LLC (FCM, USA), Apple Inc. (APNs, USA). Notifications never contain recording content (a fixed sentence and identifiers only) |
| 13 | Payment (when connected) | Payment method token, payment history (the Company does not store card numbers) | Billing | Periods required by law [법률 검토 필요 · legal review required] | Toss Payments (Korea), Paddle (overseas, merchant of record — transfer to the UK / USA) |
| 14 | Plans & usage | Per organization: transcription time, storage, AI usage, video credit ledger (the link to a user is removed on account deletion), seat kind (author / viewer, industrial plans) and the seat chosen when inviting | Limits and settlement. In an organization a platform admin assigned a plan to, new recordings and imports are limited once a limit is reached (a recording in progress is still saved) | While the organization exists | None |
| 15 | Safety alerts to admins | Recording id, the recorder's name and time of a remark judged safety-related | In organizations whose policy "always notify admins of safety remarks" is on, admins are notified in real time (app), by push and by email | Alerts are not stored (email per the mail server's policy) | Email and push never contain what was said (a link only). Admins can turn them off in notification settings |
| 16 | Sign-up abuse protection | IP and time of sign-up requests (rate limits), proof-of-work value (computed, not stored), captcha response token (when captcha is on) | Preventing automated sign-ups and spam | Rate-limit records stay in memory for one hour | Only when captcha is turned on: the token and IP go to the captcha provider (e.g. Cloudflare, hCaptcha, Google) — the provider and country will be added to section 4 when it is turned on [법률 검토 필요 · legal review required] |
| 17 | Knowledge | Knowledge cards extracted from recordings (text, conditions, quoted source remarks, speaker, time), contributors and reviewers, review / edit history, questions and answers of the ask window, expertise map (expertise indicators per topic), knowledge interviews, freshness / contradiction alerts | Managing and passing on organizational knowledge | Kept as an organizational asset while the organization exists. When the source recording is deleted, quotes and source links are removed. Speakers may ask to view, correct or delete knowledge derived from their remarks | Only for recordings that allow external AI, to Anthropic (extraction, summaries). Turning remarks into knowledge is opt-in by organization policy and personal setting; private and evaluative conversations are excluded. Use for HR evaluation or discipline is prohibited |
| 18 | Contribution recognition & rewards | Contribution records (first proposal, validation, refinement, reuse, impact, peer endorsement), points, thanks, badges, reward reports (organization admins see points per member), dispute records | Recognizing contributions and the rewards the organization defines | While the organization exists; anonymized on account deletion | None (reward report exports / webhooks are instructed by the organization). Use for HR evaluation is prohibited (fixed principle); public rankings only with the person's consent. Payment and tax are the organization's responsibility [법률 검토 필요 · legal review required: wage character, employee invention compensation] |
| 19 | Knowledge marketplace | Anonymized, de-identified copies of knowledge that both the contributor and the organization agreed to list (source organization and names removed); listing, license and settlement (revenue share) records; reports and withdrawals | Paid use by other organizations and revenue sharing with contributors | Copies are deleted on withdrawal, end of the license or an upheld report (existing licenses run for their term) | Copies are provided to other (licensee) organizations — whether they are anonymous or pseudonymous information and whether third-party provision consent is needed [법률 검토 필요 · legal review required]. Whether tax information is collected for settlement [법률 검토 필요 · legal review required]. Details: Knowledge Marketplace Terms |
| 20 | Works (work videos) | Work videos, cover images and keyframes (face blur per organization policy), scene embeddings, object tags and on-screen text (OCR) — all processed locally on the server; photo search uploads (deleted immediately); manuals and maintenance histories (may contain worker names — organizational assets, stored encrypted); equipment; SOPs, work steps and deviations from the standard; Skill Graph (skill levels computed from videos, maintenance records and verified knowledge); video credits | Passing on know-how, safety and standard work | Videos follow the recording rules; documents and equipment are deleted with the organization | Video analysis is never sent out. Only transcripts / summaries of recordings that allow external AI go to Anthropic. The Skill Graph must not be used for HR evaluation; its visibility is chosen by the person (private by default). Whether the rules on video information (personal video information) apply [법률 검토 필요 · legal review required] |
A-2. Additional outsourcing and overseas transfer (to be merged into section 4)
| Recipient | Country | Work / items | When |
|---|---|---|---|
| Anthropic, PBC | USA | Existing items + meeting notes and agenda, minutes translation, reference document excerpts, knowledge extraction and summaries | When an AI feature runs |
| Google LLC (Firebase Cloud Messaging) | USA | Device push token, fixed notification sentence, recording / item id | When notifying (if credentials are set on the server) |
| Apple Inc. (Apple Push Notification service) | USA | Device push token, fixed notification sentence, recording / item id | When notifying (if keys are set on the server) |
| Toss Payments Co., Ltd. | Korea | Payment processing | When payment is connected |
| Paddle.com Market Ltd | UK / USA | Overseas payment (merchant of record) | When payment is connected |
| Captcha provider (if configured) | Depends on the provider | Captcha response token, IP | At sign-up (only if the operator turns it on) |
A-3. Additional security measures (to be merged into section 9)
- Wider encryption at rest: besides recording files, outbox mail files (verification / notification mails left on the server when no mail server is configured or delivery failed), organization export ZIPs (exist only while being downloaded) and database backup copies are stored encrypted the same way (AES-256-GCM, a different key per file).
- Transcript and minutes content deleted from the database is overwritten so it does not remain in free space (secure delete).
- Backups: a consistent copy of the database is made while the server runs and encrypted; only the most recent backups are kept together with the recording files (14 by default), and restores are tested regularly.
- Server health monitoring (disk, GPU, queue) and alert emails to operators (no personal information).
- Field-level encryption of the transcript and minutes text inside the database is being designed together with search (design note: docs/v07-global-brand.md).
A-4. Updated data subject rights (to be merged into section 6)
- The data export ZIP now also contains
productivity.json(notes, comments, mentions, approvals, reference documents),security.json(two-step verification state, sign-in records, SSO, push devices),notes.jsonandcorrections.jsonper recording, knowledge and contributions (knowledge.json) and Works (works.json,sops.json). - On account deletion, contributions left on other people's recordings and in organizational knowledge (source remarks of knowledge cards, comments, notes, approvals, corrections, contribution and point records) are not deleted but anonymized as "deleted user", because the organization's other members keep relying on them as work records; names, emails and identifiers that could identify you are removed [법률 검토 필요 · legal review required: basis and scope of anonymization].
- You can view, correct or dispute knowledge, contribution and Skill Graph information in the "My knowledge contributions" screen and at support@metavu.io.